Privacy Policy
This Policy explains what personal data Autentique collects, how it is used, with whom it may be shared, how it is protected and how you can exercise your rights.
Autentique is a platform for creating, sending, electronically signing and managing documents, provided by Autentique LTDA, registered in Brazil under CNPJ No. 29.423.653/0001-65.
1. Scope of this Policy
This Policy applies to autentique.com.br, the Autentique platform and products and services that refer to this document. It covers data relating to visitors, account holders, senders, signers, document participants and people who contact our support team.
Information may be provided directly by you, by a person who sends a document or manages an organization on the platform, by services you authorize to connect to Autentique or by sources used for requested verification procedures. We also collect technical information when our services are used.
This Policy should be read together with our Terms of Use and notices displayed for specific features. Where an activity requires consent, authorization will be requested in a manner appropriate to that purpose. Reading this Policy or simply visiting the website does not replace that consent.
2. Personal data we may collect
2.1. Registration, identification and communications
We may process names, email addresses, telephone numbers, CPF numbers or other identifiers provided, dates of birth and information from external accounts linked to Autentique. A CPF is a Brazilian individual taxpayer identifier. The data requested varies according to the registration process, feature and requirements of the signing process.
We may also retain messages exchanged with our support team, support requests, satisfaction survey responses and feature suggestions.
2.2. Documents and signature records
We process files uploaded or imported to the platform, information entered in documents, participant details and records needed to perform and document the signing process. These records may include dates and times, access events, actions taken, IP addresses, device and browser information and the results of verification procedures used.
Documents are provided by users and may contain personal data about participants or third parties, including sensitive personal data. The person responsible for sending a document must ensure that there is a proper basis for sharing that information and requesting the intended signatures.
2.3. Identity verification and biometrics
Where the signing process uses document verification, facial biometrics or liveness checks, we may process identification document images, photographs or sequences of facial images and verification results. Biometric data linked to an individual is sensitive personal data and receives protection appropriate to that category.
This data is processed for verification procedures applicable to the document, fraud prevention and security of the signing process, subject to the information presented in the relevant workflow and applicable legal grounds.
2.4. Technical and usage information
We may collect IP addresses, access dates and times, device types, operating systems, browsers, pages and features accessed, error logs, cookies and browsing identifiers.
Location information may be derived from the connection or, where a feature requests precise location, from permission granted through the device or browser. Its accuracy and availability depend on how it is collected.
2.5. Third-party data and integrations
We may receive information from authentication providers, file storage services and databases used for identity verification, such as SERPRO and Brazil's Federal Revenue Service. Information available from public sources, including court records, may be consulted where relevant to a legitimate purpose related to our services.
Access to connected services depends on the permissions granted and the feature used. The handling of data from Google services is detailed in section 4.
2.6. Payments and billing
Payments are processed by specialist providers, such as Iugu and Stripe. These providers handle payment data under their own policies and the requirements applicable to the transaction.
Autentique may process information needed to manage plans, charges and invoices, such as customer identification, billing references and payment status. Full card numbers and card security codes are not stored by Autentique.
3. How we use data
We use the data necessary to:
- Create, manage and protect accounts, authenticate access and provide the platform.
- Prepare, send, sign, store and make documents available to authorized participants.
- Perform identity checks, prevent fraud and preserve signature records.
- Send operational communications, such as signature requests, document notifications, billing notices and support responses.
- Manage contracts, plans and payments.
- Diagnose failures, evaluate service performance and improve features and the user experience.
- Conduct satisfaction surveys and, where permitted, send promotional communications or display advertising.
- Comply with legal and regulatory obligations and exercise rights in administrative, judicial or arbitration proceedings.
Depending on the activity and the nature of the data, processing relies on grounds permitted by law, such as performance of a contract, compliance with legal obligations, exercise of rights, fraud prevention, legitimate interests or consent, where applicable. Sensitive data is subject to the specific legal grounds provided for that category.
3.1. Advertising and promotional communications
We may use information about interactions with our website and campaigns to evaluate results and provide relevant communications or advertising, subject to applicable rules and choices. You may request that promotional communications stop through the channel indicated in the message or by contacting our support team.
Data obtained from Google services, documents imported from Google Drive and information derived from them are not used for advertising, ad targeting or sharing with advertising platforms. Communications needed for the operation of an account or document are separate from promotional communications.
3.2. Machine learning and artificial intelligence
The development and improvement of Autentique features may involve machine learning and artificial intelligence techniques, subject to the stated purposes, applicable law and the restrictions in this Policy. This provision does not constitute unrestricted permission to use personal data or documents.
We do not use information obtained from external sources, such as OAuth login and integrations with Google Drive, Dropbox or other storage services, to train artificial intelligence or machine learning models. Data from Google services, including imported documents and information derived from them, is also subject to the restrictions in section 4.
If a new feature involves processing that has not previously been disclosed, its purposes and the data involved will be communicated in advance, and consent will be obtained where necessary.
4. Data obtained from Google services
4.1. Signing in and registering with a Google Account
When you choose to sign in or register with your Google Account, we receive identification data, such as your name, email address and account identifier. We use this information to create or locate your account, authenticate your access and link your Google Account to your Autentique account. We do not receive your Google password.
4.2. Importing files from Google Drive
When you choose to import a document from Google Drive, we use Google's file picker so that you can select the file you want to make available to Autentique. The import may access the content and necessary information about the selected file, such as its identifier, name, type and modification date.
The file is transferred to Autentique to prepare the document and enable the requested signing workflow. Supported Google file formats may be converted to PDF during import. The imported document will be made available to signers and other participants according to the permissions and sharing settings established on the platform.
This feature does not create a general copy of, or synchronize, your entire Google Drive. Selecting a file also does not authorize its use for purposes unrelated to the requested service.
4.3. Purposes and restrictions
Data received from Google is used for the features described in this section and their operation and security. We do not sell this data or use it for advertising or credit assessment. We also do not transfer it to advertising platforms or data resellers.
We do not use data received through Google or Google Workspace APIs, imported document content or information derived from them to develop, improve or train artificial intelligence or machine learning models, including general-purpose models.
4.4. Sharing and human access
Sharing takes place to the extent necessary to perform authorized features, such as making a document available to designated participants and using infrastructure, storage and support providers subject to data protection obligations.
Our personnel and providers may access the content of this data only with your specific authorization or where necessary for security, investigation of failures or abuse, or compliance with the law, within the limits of Google's policies. This Policy does not, by itself, constitute authorization for indiscriminate human reading of documents.
4.5. Storage, protection and credentials
Identification information needed for the account and imported documents are stored in systems used by Autentique, subject to the purposes and retention rules in this Policy. We apply access controls and encryption in transit and at rest to data obtained from Google services.
Authorization credentials, such as tokens, are used exclusively to enable authorized features, with restricted access and protection against misuse. Their use depends on the continued validity of the authorization granted by Google and by you.
4.6. Revocation, retention and deletion
You can revoke Autentique's connection in your Google Account settings. Revocation prevents further access through the revoked authorization but does not automatically remove data or documents already transferred to Autentique.
Identification data is retained for the period necessary for the account and the stated purposes. Imported documents become part of the signing workflow and follow the retention criteria in section 9. To request deletion, email contato@autentique.com.br or dpo@autentique.com.br. Any retention after your request is limited to circumstances justified under that section.
4.7. Google policy and Limited Use
The use of information received through Google APIs and its transfer to other applications comply with the Google API Services User Data Policy, including applicable Limited Use requirements, and the relevant Google Workspace rules.
The restrictions in this section take precedence over general provisions in this Policy or the Terms of Use that might otherwise permit broader use of this data.
5. Cookies and similar technologies
We use cookies, browsing identifiers, access logs and similar technologies to maintain sessions, remember preferences, protect the platform, understand its use and evaluate our services and campaigns.
Some of these technologies are provided by third parties. Their use depends on their purpose and applicable rules, including consent where required. The restrictions in section 4 also apply to any Google data that may be associated with these activities.
You can manage cookies through your browser settings and, where available, the controls presented on the website. Disabling resources needed for operation may affect access and certain features.
6. With whom we may share data
We may share data with participants and organizations involved in documents, according to their permissions, and with providers needed to operate Autentique. Services used include:
- Google Analytics: analysis of website and platform access and usage. Privacy policy.
- Intercom: user support and communications, including identification, conversations and context needed for assistance. Privacy policy.
- Wootric: satisfaction and NPS surveys, using the data needed to conduct and record the survey. Privacy policy.
- Statuspage: communications about service availability and incidents to people who request these notifications. Privacy policy.
- Iugu and Stripe: payment processing and management of charges relating to purchased plans. Iugu policy and Stripe policy.
- SERPRO: identification and biometric checks and validation, depending on the verification method used. Privacy policy.
We also use infrastructure, storage and communication services needed to deliver the platform. Sharing must be consistent with each service's purpose and limited to necessary data.
Data may be provided to authorities where there is a legal obligation, valid order or other applicable legal ground. The specific restrictions on Google services data continue to apply to all providers and sharing. Listing a provider in this section does not mean that it receives all data processed by Autentique.
7. Storage and international transfers
Our services and providers may use infrastructure located in Brazil or other countries. Where personal data is transferred internationally, the mechanisms and safeguards required by applicable law will be observed.
You may request information about the processing of your data and the corresponding sharing by contacting dpo@autentique.com.br.
8. Protecting information
We adopt technical and administrative measures intended to prevent unauthorized access, loss, alteration and improper disclosure. These measures include access controls, protection of communications and stored files, and restricting access to personnel and providers who need the data for their authorized activities.
Files and support information that may contain sensitive data are protected by encryption in transit and at rest. Data from Google services is also subject to the specific measures described in section 4.
You should protect your login credentials and report suspected misuse of your account to our support team.
9. Retention and deletion
We retain personal data for the period necessary for the stated purposes, taking into account the nature of the information, our relationship with you, legal obligations, applicable contracts and the need to preserve evidence and exercise rights.
Closing an account or revoking an integration does not, by itself, result in the deletion of signed documents and their records. Information needed for the integrity, authorship, validity and auditing of documents may remain stored while there is a basis and a need for its retention.
Where applicable upon account closure, access will be blocked and ordinary communications relating to its use will stop. Data that must still be retained will be restricted to the purposes that justify that retention.
You may request deletion of your account or personal data through our support team or by emailing contato@autentique.com.br. The request will be assessed taking into account the data involved, retention obligations and the rights of other participants. Where certain information cannot be deleted, the applicable reasons will be explained.
Once the purposes and grounds justifying retention have ended, the data will be deleted or anonymized, as applicable.
10. Your rights
Under the Brazilian General Data Protection Law, and subject to applicable conditions, you may request confirmation of and access to the processing of your data, correction of information, details of sharing, portability, anonymization, blocking or deletion. You may also withdraw consent, learn about the consequences of not providing it and object to unlawful processing.
To exercise your rights, contact dpo@autentique.com.br. We may request proportionate information to confirm your identity and prevent data from being disclosed to unauthorized third parties. If your request depends on the person who sent the document or another responsible organization, we will provide guidance on the appropriate contact.
You may also submit requests or complaints to Brazil's data protection authority, the ANPD. Requests will be handled in accordance with the terms and time limits applicable to their nature.
11. External services and linked accounts
Autentique may offer links and integrations with external services, including login and storage providers such as Google and Dropbox. Processing performed directly by those services is governed by their respective policies.
This Policy continues to apply to information Autentique receives and processes through those integrations. The existence of a link or integration does not mean that Autentique can access all data in an external account.
12. Updates and contact
We may update this Policy to reflect changes to our services, processing practices or applicable requirements. Material changes will be communicated through the website, the platform or email, as appropriate. Where a change requires new authorization, it will be requested before the corresponding processing takes place.
For questions about privacy and data protection, contact dpo@autentique.com.br. For support and account-related requests, contact contato@autentique.com.br.